Vulnerability Engineer

Coforge

Greater London

Hybrid

GBP 60,000 - 90,000

Full time

16 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Coforge is seeking a Vulnerability Engineer in London, UK to own end-to-end vulnerability investigation and remediation across the workstation estate. The role requires analysing findings from Qualys, prioritising actions by impact and feasibility, and delivering fixes that address root causes.

You will develop PowerShell automation for detection, remediation and reporting, while troubleshooting SCCM/MECM client health and deployments.

Qualifications

  • Experience in vulnerability management and remediation.
  • Proficiency with Qualys or equivalent security platforms.
  • Automation skills with PowerShell and endpoint tooling.
  • Hands-on experience with Microsoft SCCM/MECM.

Responsibilities

  • Own investigation and remediation of complex endpoint vulnerabilities across the workstation estate.
  • Analyse findings from Qualys and other security platforms, prioritise by risk and feasibility.
  • Perform root cause analysis for vulnerabilities and remediation failures.
  • Design, test and deliver fixes to remove root causes and reduce manual remediation.
  • Develop and maintain PowerShell automation for detection, remediation and reporting.
  • Troubleshoot SCCM/MECM client health and deployment issues.
  • Prepare documentation, runbooks and audit evidence.
  • Assist with change controls and security policy alignment.

Skills

Vulnerability
Qualys
PowerShell
SCCM/MECM

Tools

PowerShell
SCCM/MECM

Job description

Work-mode: Hybrid - 3 days weekly from office

Skills: Vulnerability, Qualys, PowerShell and Microsoft SCCM/MECM

We at Coforge are looking for Vulnerability Engineer in London, UK.

Scope & Description of Required Work
  • Own the technical investigation and remediation of complex endpoint vulnerabilities across the workstation estate.
  • Analyse and prioritise findings from Qualys and other approved security platforms, considering technical impact, business risk and remediation feasibility.
  • Perform structured root cause analysis for vulnerabilities, failed deployments, recurring non-compliance and endpoint health issues.
  • Design, test and deliver sustainable engineering fixes that remove underlying causes and reduce repeated manual remediation.
  • Create, test, peer review and deploy enterprise application packages, security updates and configuration changes through Microsoft SCCM/MECM and related endpoint tooling.
  • Develop and maintain PowerShell automation for detection, remediation, validation, reporting and operational health checks.
  • Troubleshoot SCCM/MECM client health, software distribution, content delivery, deployment status and patch installation failures.
  • Use controlled pilot groups, technical validation and rollback planning to reduce deployment risk.
  • Work with the End User Platform and Security teams to agree remediation strategy, technical ownership and delivery priorities.
  • Recommend improvements to packaging standards, deployment controls, vulnerability workflows, reporting and endpoint engineering processes.
  • Produce clear technical documentation, remediation records, runbooks, knowledge articles and audit evidence.
  • Provide accurate progress, risk and dependency updates for vulnerability, compliance and service reporting.
  • Support remediation across physical workstations, laptops and Citrix virtual desktop environments.
  • Apply ITIL best practice across Incident, Request, Problem and Change management activities.
  • Perform system administration and advanced troubleshooting within Windows, Active Directory, Group Policy and Microsoft 365 environments.
  • Ensure solutions comply with TMHCC security policies, technical standards, controls and agreed service levels.
Out of Scope
  • Activities not explicitly listed in the Scope & Description of Required Work.
  • Changes to production services that have not completed the required TMHCC change control and approval process.
  • Ownership of security policy, risk acceptance decisions or business risk sign-off.
  • Work on unsupported platforms or systems outside the agreed endpoint estate unless separately authorised.
Deliverables & Delivery Milestones
  • Prioritised vulnerability remediation backlog based on approved security data and agreed delivery priorities.
  • Tested and peer-reviewed SCCM/MECM packages, security updates and configuration changes.
  • Production-ready PowerShell detection, remediation and validation scripts.
  • Root cause analysis records for recurring vulnerabilities, failed deployments and endpoint health issues.
  • Pilot, validation and rollback evidence for controlled deployments.
  • Runbooks, knowledge articles, remediation records and audit evidence.
  • Regular progress, risk, dependency and outcome reporting.
  • Delivery milestones and target dates to be agreed during onboarding and maintained through the applicable planning and change processes.
Acceptance Criteria
  • Agreed vulnerability remediation activities are completed in line with approved priorities, change controls and service levels.
  • Delivered packages, scripts and configuration changes pass agreed testing, peer review, pilot and technical validation requirements before production deployment.
  • Remediation includes clear evidence of outcome, validation results and rollback arrangements where applicable.
  • Root causes and recurring failure patterns are documented, with permanent engineering actions or technical debt items recorded where required.
  • Technical documentation, runbooks, knowledge articles, remediation records and audit evidence are complete, accurate and stored in the agreed TMHCC location.
  • Progress, risks, dependencies and blockers are reported accurately through the agreed governance process.
  • Solutions comply with TMHCC security policies, technical standards and operational processes.
  • Deliverables are accepted by the TMHCC Hiring Manager or nominated technical owner.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Analyst
Vulnerability Analyst

Computacenter • England

On-site
GBP 45,000 - 60,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

HCLTech • Greater London

Hybrid
GBP 90,000 - 120,000
Vacation per year
Term life insurance
Business travel insurance
Vulnerability Management Engineer
Vulnerability Management Engineer

Opus Recruitment Solutions • United Kingdom

Remote
GBP 50,000
Travel and food expenses fully reimbursed
Endpoint Deployment & Manual Remediation Analyst
Endpoint Deployment & Manual Remediation Analyst

HCLTech • Greater London

Hybrid
GBP 45,000 - 65,000
Cyber Security Analyst-VM
Cyber Security Analyst-VM

Wipro • West of England

On-site
GBP 60,000 - 90,000
Senior Security Engineer
Senior Security Engineer

Guidant Global • Reading

Hybrid
GBP 101,000 - 138,000
Cyber Security Analyst
Cyber Security Analyst

Wipro • Greater London

Hybrid
GBP 65,000 - 90,000
Pension (contributory up to 5%)
Life insurance 4x
Private medical insurance
Cybersecurity Analyst – Vulnerability Management
Cybersecurity Analyst – Vulnerability Management

Digital Realty • Greater London

Hybrid
GBP 75,000 - 110,000
Vulnerability & Threat Exposure Manager (Contract, Inside IR35)
Vulnerability & Threat Exposure Manager (Contract, Inside IR35)

Lorien • Greater London

Hybrid
GBP 75,000 - 100,000
Hybrid work model
London office access
Cyber Security Analyst-VM
Cyber Security Analyst-VM

Wipro Limited • Norwich

On-site
GBP 42,000 - 65,000